# VPNCheap Apple Native Customer Feedback Improvement Plan

Date: 2026-07-31  
Mode: planning only  
Plan confidence: **88/100**. Close purchase and node freshness with real Store/device evidence, then make the supported iOS policy unambiguous. This is an executive judgment score, separate from fingerprint priority.

Governing contract: [Feedback-to-Roadmap Decision Contract v1.0, 2026-07-31](https://vpncheap-feedback-brief-20260731.pages.dev/feedback-to-roadmap-decision-contract.md)

## Evidence and state

- **OBSERVED:** membership expiry updated server-side after purchase while the client stayed stale.
- **MEASURED:** change polling and forced product refresh exist with tests; no released-build purchase receipt closes the report.
- **MEASURED:** build configuration targets iOS 17 while project documents also claim iOS 15 and 15.6/16.

`△△ ☐☐☐ | 0/2/3/0`

| State | IDs | Local obligation |
|---|---|---|
| `△` | VPN-03, VPN-12 | Purchase and node self-heal code exists; real device/store verification is missing. |
| `☐` | VPN-17, VPN-19, VPN-13 adoption | Shared freshness, support policy, and signed capability remain incomplete. |

```text
BEFORE  purchase succeeds -> old expiry remains -> user relogs
AFTER   receipt -> server revision changes -> UI refreshes -> receipt linked
```

## Execution sequence

Order follows dependency and owner sequence, not numeric rank. Canonical fingerprint scores and program-value judgments are different decision ledgers and are not directly comparable.

Scores below are canonical registry references, not local rescores: item 1 -> VPN-03; item 2 -> VPN-12; item 3 -> VPN-19; item 4 -> VPN-13.

### 1. Purchase and account freshness: 78/100, P1

Breakdown: `24 + 7 + 12 + 15 + 10 + 10`.

**PROPOSED:** run StoreKit sandbox and approved production paths for purchase, renewal, restore, delayed server update, background/resume, account switch, empty response, and timeout. UI shows safe pending/stale state and never discards a newer server generation.

### 2. Native node-state release matrix: 81/100, P1

Breakdown: `24 + 15 + 12 + 15 + 5 + 10`.

**PROPOSED:** share the cross-client matrix while keeping Apple acceptance on a real device and NetworkExtension state.

### 3. Support-policy source of truth: 53/100, P3

Breakdown: `8 + 3 + 20 + 10 + 5 + 7`.

**PROPOSED decision:** publish iOS 17 as the current supported baseline, **82/100**, because it matches the build source of truth and avoids promising untested compatibility. Lowering to iOS 15 before compatibility, dependency, device, and store evidence scores **43/100**.

The chosen value must drive project generation, App Store copy, QA matrix, support scripts, and portfolio index.

### 4. Signed capability adoption: 54/100, P3 evidence gate

Breakdown: `24 + 3 + 5 + 15 + 0 + 7`.

Inventory the current generic client identity and session/token flow; adopt the Xboard contract only after it is versioned. UA-only blocking scores **18/100** because it is spoofable and would break clients with inconsistent current identifiers.

## Phases and acceptance

- **0-30:** execute purchase/node verification cards; reconcile current deployment targets, project generation, Store copy, QA, and support evidence for the support baseline without publishing a decision; freeze the P1/P2 freshness envelope with Xboard. This is ordinary evidence collection, not P3 acceleration, and no exception is claimed.
- **31-60:** implement only failed P1/P2 paths and a stale/pending state.
- **61-90:** after scheduled P0-P2 gates close, choose and publish the support baseline and derive all support declarations from that source; then canary release and monitor purchase-to-fresh latency, no-node, forced refresh, re-login-required, and support-policy mismatch events.
- `○` requires Store/device round trip and, for VPN paths, real NetworkExtension transition plus changed public egress.

### Phase gates

- **0-30:** evidence coverage reaches 100%.
- **31-60:** every scheduled P1/P2 acceptance is complete or explicitly approved `X`.
- **61-90:** two canary windows close without regression.
- Stop immediately on any listed guardrail.
- No P3 acceleration is claimed; support-baseline publication and source derivation start in 61-90 only after P0-P2 gates close. Signed capability remains at its evidence gate unless separately approved under the governing contract.

## Guardrails

- NetworkExtension status and core signals own connection truth.
- Never log or display ingress address, node protocol, raw config, or subscription URL.
- Preserve list-based node UI, Liquid Glass rules, encrypted credentials, and four-language behavior.
- Stop on receipt/account mix-up, rollback to stale expiry, tenant/user crossover, or network-detail leakage.
